Review audit events logged in Omnissa Identity Service to monitor provisioning activity and to troubleshoot provisioning errors. Use these logs along with your third-party identity provider provisioning logs for a comprehensive look at the various stages of provisioning users and groups from your third-party identity provider to Omnissa services.
Omnissa Identity Service logs include:
-
Successful events related to provisioning from your third-party identity provider to Omnissa Identity Service
For errors related to provisioning from the third-party identity provider to Omnissa Identity Service, review the provisioning logs in the identity provider. For more information, see Review Identity Provider Provisioning Logs.
-
Successful events and errors related to provisioning from Omnissa Identity Service to the Omnissa services configured for Omnissa Identity Service, such as Workspace ONE UEM and Omnissa Access
Separate audit events are created for the different stages of provisioning, and for each Omnissa service. For example, if Omnissa Identity Service is configured for both Omnissa Access and Workspace ONE UEM, when a user is created in the identity provider and successfully provisioned to Omnissa Identity Service, Omnissa Identity Service records three audit events:
- An event for provisioning the user in Omnissa Identity Service (if successful)
- An event for provisioning the user in Omnissa Access (whether successful or unsuccesful)
- An event for provisioning the user in Workspace ONE UEM (whether successful or unsuccessful)
Audit events are created in Omnissa Identity Service whenever a user, group, directory, or attribute is created, updated, or deleted, and whenever a group membership changes, that is, a user is associated or disassociated with a group. The status of the audit event indicates whether the action succeeded or failed. You can also view details about each event to troubleshoot problems.
Audit events are saved for 90 days.
Viewing Audit Events
You can view all audit events in the Events tab of the Omnissa Identity Service directory.
As a large number of audit events are generated, you can use search and filters to narrow the results. For example, you can view audit events for a specific user, view all events with a failed status during a specific timeframe, or view all events related to group membership.
The Events tab displays a maximum of 10,000 events. Keep in mind that additional events might be stored in the Omnissa Identity Service database. Use search and filters to view the most relevant events for your troubleshooting scenario.
Note: For inbound provisioning (provisioning from the third-party identity provider to Omnissa Identity Service), only successful events appear in Omnissa Identity Service logs. For errors, review the identity provider provisioning logs. See Review Identity Provider Provisioning Logs for more information.
-
Navigate to Omnissa Identity Service.
- Cloud: Log in to the Omnissa Connect console, select Identity Management > End User Management from the left pane, then click Launch End User Management.
- On premises: Log in to the Omnissa Access console, select Integrations > Identity Service, then click Configure SCIM Provisioning.
Omnissa Identity Service opens in a new tab in the browser.
-
On the directory card, click View.
-
Select the Events tab to view the audit events for the directory.

For each audit event, you can see the following information:
Time The date and time of the event (in your local timezone) Activity The type of activity: Create, Update, Delete, Link, or Unlink
Link events are created when a user is added to a group and Unlink events are created when a user is removed from a group.Status Success or Fail Object Type User, Group, Membership, Attribute Alias, or Directory
Membership refers to group membership events. Attribute Alias refers to attribute events.Object Name Object Name is the username for users, directory name for directories, group name for groups, username for memberships, and attribute name for attributes Service The destination service: IS (Omnissa Identity Service), Access (Omnissa Access), or UEM (Workspace ONE UEM) Message Provides more details about the event -
Use search and filters to customize your view, if required.
-
You can search for an object such as a user or group by typing the first few letters of the object name in the search box. For users, type the userName value, that is, the login name.
Note that this is not a wildcard search. You must type the first few letters of the name.
For example:

-
You can select the time range for which to view events.

-
You can filter events by the type of activity, status, object type, and service. For example:

-
-
To view more information about an audit event, click the View Details link.
Relevant information includes:
-
Failure messages
For events with a Fail status, look for the
"failureMessage"line which provides information about the error.For example:

-
The
resourceIdInTargetvalue, which is the ID of the object in the Omnissa service to which it is provisioned. For example:
-
Exporting Audit Events
You can export audit events to a .csv file. A maximum of 10,000 events are exported.
Important: Keep in mind that additional events might be stored in the Omnissa Identity Service database. Use search and filters to view and export the most relevant events for your troubleshooting scenario.
-
Navigate to Omnissa Identity Service.
- Cloud: Log in to the Omnissa Connect console, select Identity Management > End User Management from the left pane, then click Launch End User Management.
- On premises: Log in to the Omnissa Access console, select Integrations > Identity Service, then click Configure SCIM Provisioning.
Omnissa Identity Service opens in a new tab in the browser.
-
On the directory card, click View.
-
Select the Events tab.
-
Use search and filters to display the data that you want to save, then click Export.

The audit events are exported to a file named
Reports.csv. The columns in the file match those in the user interface. Filters and sorting applied in the user interface are also applied to the exported data. The timestamps are based on your local timezone.
Viewing Audit Events from the Users and Groups Tabs
In addition to the Events tab, audit events for users and groups also appear in the Users and Groups tabs, after the users and groups are successfully created in the Omnissa Identity Service directory.
Note: For inbound provisioning (provisioning from the third-party identity provider to Omnissa Identity Service), only successful events appear in Omnissa Identity Service logs. For errors, review the identity provider provisioning logs. See Review Identity Provider Provisioning Logs for more information.
-
Navigate to Omnissa Identity Service.
- Cloud: Log in to the Omnissa Connect console, select Identity Management > End User Management from the left pane, then click Launch End User Management.
- On premises: Log in to the Omnissa Access console, select Integrations > Identity Service, then click Configure SCIM Provisioning.
Omnissa Identity Service opens in a new tab in the browser.
-
On the directory card, click View.
-
Select the Users or Groups tab.
-
Find the user or group.
You can use the filters on the columns to filter the list.
-
Expand the row, then select the Events tab.
For example:

-
Click the View Details link to view more information about the event.
Was this page helpful?